March 9, 2023, 1:02 p.m. |

Ubuntu security notices ubuntu.com

It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)

Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel
did not properly handle VLAN headers in some situations. A local attacker
could use this to cause a …

code crash cve denial of service free headers kernel linux linux kernel local netfilter protocol protocols service sockets state subsystem system use-after-free usn vlan vulnerabilities vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Director, Risk Compliance & Trust (GRC)

@ Snyk | Boston, London

Working Student (f/m/d) - Security Architecture Project Management & Communications

@ SAP | Walldorf, DE, 69190

Werkstudent Cyber Security (w/m/x)

@ BMW Group | München, DE